vendor:
Gift Voucher
by:
Renos Nikolaou
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Gift Voucher
Affected Version From: 1.0.5
Affected Version To: 1.0.5
Patch Exists: YES
Related CWE:
CPE: a:codemenschen:gift_voucher:1.0.5
Platforms Tested: Windows 10
2018
WordPress Plugin Gift Voucher 1.0.5 – ‘template_id’ SQL Injection
The vulnerability allows an attacker to inject SQL commands on 'template_id' parameter.
Mitigation:
Update to the latest version of the plugin.